Vulnerability Description
SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator console, to expose unauthenticated access to the file system and upload a malicious file. The attacker or another user can then use a separate mechanism to execute OS commands through the uploaded file leading to Privilege Escalation and completely compromise the confidentiality, integrity and availability of the server operating system and any application running on it.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver Application Server Java | 7.20 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/162086/SAP-Java-OS-Remote-Code-Execution.htThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2021/Apr/7Mailing ListThird Party Advisory
- https://launchpad.support.sap.com/#/notes/2979062Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=562725571Vendor Advisory
- http://packetstormsecurity.com/files/162086/SAP-Java-OS-Remote-Code-Execution.htThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2021/Apr/7Mailing ListThird Party Advisory
- https://launchpad.support.sap.com/#/notes/2979062Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=562725571Vendor Advisory
FAQ
What is CVE-2020-26820?
CVE-2020-26820 is a vulnerability with a CVSS score of 7.2 (HIGH). SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator console, to expose unauthenticated access to the fi...
How severe is CVE-2020-26820?
CVE-2020-26820 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-26820?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Netweaver Application Server Java.